Last updated: April 24th, 2025
At QRSurge, protecting your privacy is core to how we build our product. This policy is our plain-language guide to:
We've kept the legalese to a minimum and added tables and examples so everything is easy to understand. If anything still seems unclear, email us at [email protected] and you'll hear back from a real human.
ThinkSource Software, LLC d/b/a QRSurge
7901 4th St N # 26674, St. Petersburg, FL 33702, USA
• Controller – We decide how to use information about visitors, customers, and prospects.
• Processor – We handle “scanner” data on behalf of our customers when someone scans one of their QR codes or visits a short link.
Contact us: [email protected] (general) | [email protected] (EU/UK matters)
qrsurge.com
, app.qrsurge.com
, qrsurge.to
, qrs.so
)What we collect | Examples | How we get it |
---|---|---|
Account details | Name, email, login profile, password hash | You or Google/Microsoft login |
Billing info | Name, address, last-4 digits of card (stored by Stripe) | You / Stripe |
Usage data | Pages you visit, clicks, device type, language, time zone | Automatic |
Location (coarse) | Country, state, city, ZIP, rough latitude/longitude | Derived from IP |
Files you upload | Logos, images, PDFs | You |
Support messages | Emails, chat transcripts | You |
We don't request or knowingly collect sensitive data (health, biometrics, children's data, etc.).
Why | Legal reason (GDPR) |
---|---|
Run and secure our service | Contract |
Process payments and invoices | Contract / Legal obligation |
Fix bugs and improve features | Legitimate interest |
Send account or security emails | Contract |
Send product news or offers | Consent (opt-in) / Legitimate interest (B2B) |
Show customers QR-code scan stats | Contract (processor duty) |
Meet legal duties and stop fraud | Legal obligation / Legitimate interest |
We never sell or share your info for targeted ads.
We sometimes turn data into anonymous stats—like total scans per country—to spot trends. Those stats can't identify you, and we won't try to reverse-engineer them.
Essential cookies
authjs.*
– keeps you signed incampaign_password
– lets password-protected scan pages workPreferences
organizationSlug
, sidebar:width
, tz
, plus theme
in localStoragePayments
Stripe sets its own cookies during checkout.
You'll see a banner the first time you visit; you can change cookie settings any time. Full details are in our separate Cookie Notice below.
Our site sometimes links to other websites (docs, blogs, etc.). We aren't responsible for their content or privacy practices. Please read their policies if you visit them.
Partner | What they do | Where data goes |
---|---|---|
Fly.io | Hosts our dashboard | USA |
Cloudflare | Edge hosting, DNS, anti-bot | Worldwide |
Neon.tech | Stores our database | USA |
Stripe | Handles payments | USA |
Resend | Sends our emails | USA |
Simple Analytics | Privacy-friendly site analytics | Netherlands |
Sentry | Error monitoring | USA / EU |
Our servers live in Virginia (USA). When EU/UK data comes to the US, we rely on the EU's Standard Contractual Clauses plus strong encryption and access controls. We may certify under the EU–US Data Privacy Framework in the future.
Data | How long |
---|---|
Active accounts | Until you close the account |
Deleted accounts | Wiped within 30 days |
Payments & tax records | At least 7 years (required by law) |
Scanner IP addresses | Anonymized right after we get the location |
Logs & analytics | About 12 months, then aggregated or deleted |
Back-ups | Overwritten on a rolling basis (usually within 90 days) |
We'll tell you and, where required, the authorities without undue delay if a data breach happens.
Depending on where you live, you can:
Send requests to [email protected]. We answer within 72 hours (and within 30 days for EU/UK).
Do-Not-Track: Browsers' “DNT” signals aren't widely supported, so we don't respond to them. Use our cookie settings or email us instead.
California, Virginia, Colorado, Connecticut
You can know, access, correct, delete, or export personal info and opt out of sale/share, targeted ads, or certain profiling. Email [email protected]; we'll reply within 45 days (or 90 days if we need more time). If we deny your request, you can appeal by emailing “Appeal” in the subject.
Shine-the-Light (CA)
Ask us once a year who we shared direct-marketing info with.
Nevada
Email us with “Nevada Do Not Sell Request” to opt out of future “sales” (as Nevada defines them).
QRSurge is for adults 18+. If you think a minor gave us info, let us know and we'll delete it.
If we make big changes, we'll post a notice in the app or email you at least 14 days before they take effect. We keep old versions for reference.
Need this policy in another format? Email [email protected] and we'll help.
If you share a QR code or short link publicly, others can copy or cache it. Deleting the campaign won't remove every copy. To stop traffic, deactivate the code in your dashboard.
Last updated: April 24th, 2025
Cookies are small text files stored on your device. We also use localStorage and similar tech for the same purposes.
Category | Why | Examples |
---|---|---|
Strictly necessary | Authenticate users, protect against CSRF, maintain session state | authjs.callback-url , authjs.csrf-token , authjs.session-token (30 days), campaign_password (7 days) |
Functional | Store UI and org preferences | organizationSlug (session), sidebar:width (7 days), tz (1 year), theme (localStorage) |
Analytics | Understand feature usage (cookieless, no personal IDs) | Simple Analytics (no cookies) |
Third-party payments | Enable secure checkout via Stripe | Stripe cookies such as __Secure-has_logged_in , __stripe_orig_props , _ga , stripe.csrf , etc. |
Future advertising | We will request consent before adding marketing pixels | N/A |
• Use our banner's “Cookie Settings” to toggle non-essential cookies.
• Clear cookies via your browser settings.
• Opt out of Stripe cookies via their cookies policy.
If we introduce new cookies or change purposes, we'll update this notice and refresh your consent choice.
Questions about cookies? Email [email protected].
Using our services means you agree to this Privacy Policy and Cookie Notice. Check back for updates.
QR Code Generators
Bluesky QR Code Generator